This page aggregates publicly disclosed CVE and security risk information related to 1-script, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2008-2638 | Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php. | [email protected] | 10.0 | 3.86% | 2008-06-10 | 2026-04-23 |
| CVE-2005-4091 | Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | [email protected] | 4.3 | 1.75% | 2005-12-08 | 2026-04-16 |